cyb3rfox/Aurora-Incident-Response
Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2276
- days_rel: n/a
- days_push: 1063
- n_releases_24m: 0
Adoption not part of the score
1078 stars · 130 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A cross-platform Electron desktop application for documenting incident response investigations. It digitizes the SANS FOR508 'Spreadsheet of Doom' to help responders track findings, tasks, lateral movement, and timelines while producing reports.
Use cases
- track findings and tasks during an incident response investigation
- visualize lateral movement paths in a security incident
- build a visual timeline of attacker activity
- generate incident response reports from case notes
- replace spreadsheets for DFIR case management
When to choose
- you are an incident responder managing a DFIR case and need structured documentation
- you want a free, offline desktop tool for tracking investigation findings and timelines
- you want to move beyond ad-hoc spreadsheets for incident documentation
When to avoid
- you need a team-based, server-backed incident management platform with multi-user collaboration
- you need automated evidence collection or SIEM-style alerting rather than manual documentation
- you require a mobile-first solution, as tablet support is not yet available
Facets
application · maturity maintenance
developer-tools documentation security developer-tools windows cross-platform incident-response dfir case-management forensics electron-app linux macos electron
1 source
- readme: https://github.com/cyb3rfox/Aurora-Incident-Response · fetched 2026-08-28 · ed51fa84eb72
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cyb3rfox/Aurora-Incident-Response | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="cyb3rfox/Aurora-Incident-Response")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem